This is a real, anonymized CyberTI processing record. It shows how one potential brand-impersonation candidate moved from discovery through automated evidence collection to a confirmed platform outcome.
Case at a glance
The candidate was first observed on 18 July 2026 at 09:55:26 UTC. Its second-level-domain match mapped exactly to a protected brand asset. The underlying domain, brand, customer identity, evidence image, and raw indicators are intentionally withheld.
Investigation workflow
Potential impersonation discovered
A candidate entered the phishing workflow with a preliminary score of 60. Brand-plus-keyword context was one of the recorded scoring signals.
Protected asset matched
The platform created two asset-match records. The recorded match type was
brand_in_sldwith similarity 1.00.Infrastructure enriched
DNS, HTTP, RDAP, screenshot, and TLS stages all returned an
okprocessing result. DNS resolution, HTTP reachability, and active TLS were recorded.Evidence consolidated
Five observations were attached during the enrichment window, giving the investigation a single evidence trail rather than disconnected lookups.
Outcome recorded
The platform record ended with severity confirmed, final score 100, and global status triaged phishing.
What the case demonstrates
- Asset context can turn a generic suspicious-domain signal into an organization-relevant investigation.
- Automated network and registration checks can assemble evidence before an analyst reviews the final disposition.
- A structured outcome preserves what the platform observed and how the record ended.
Privacy, method, and limitations
The case is based on one production record read through aggregate and metadata-only queries. No domain, customer, brand, matched term, source content, actor, IOC, or screenshot is published. The approximately 21-second figure measures the first-to-last automated observation timestamps, not human triage time. A specific analyst identity and human decision timestamp were not available, so no such claim is made.